Security Analysts

SOC analyst career path: moving to GRC and beyond

Most analysts leave L1 within a few years, either up into deeper SOC work or sideways into a specialty. GRC is one of the most common moves, because the SOC already taught you how controls fail in real life. It is one path among several, and the right one depends on which part of the queue you actually enjoy.

Below are the moves SOC analysts make most often, what each one asks for, and a first step you could take this week. If you are not sure which one fits, tell Carmen what you do now and which tickets you secretly like.

Talk to Carmen

Your AI career coach

Say it the way you’d say it to a friend. Carmen will ask what she needs to know.

Free, no sign-up to start.

$129,180 a year

Median information security analyst pay, May 2025

BLS Occupational Outlook Handbook

$138,650

Median pay in the information industry, May 2025

BLS Occupational Outlook Handbook

About 14,100

Openings projected each year

BLS Occupational Outlook Handbook

Where SOC analysts move next

  • GRC analyst

    Maps controls to frameworks like NIST CSF, ISO 27001 or SOC 2, runs risk assessments, and gathers audit evidence. Suits analysts who write clear tickets and like knowing why a control exists. Less on-call, more meetings and documents.

    What it takes
    Framework knowledge matters more than a certification to start. CISA later requires five years of information systems audit, control or security experience within the prior ten years, per ISACA.
    First step
    Pick one control your SOC monitors, such as MFA or logging, and write up how you would prove to an auditor that it works.
  • Incident responder

    Takes over when an alert turns into a real incident: scoping, containment, forensics and the report afterwards. Suits L2 and L3 analysts who like the hard tickets and stay calm when things are on fire.

    What it takes
    Usually one to three years in a SOC plus solid Windows and Linux forensics. Some teams expect on-call rotations.
    First step
    Volunteer to write the timeline for the next confirmed incident your team handles, and ask the lead to review it.
  • Threat intelligence analyst

    Tracks attacker groups and techniques, then turns that into briefings and detections your team can use. Suits analysts who read threat reports for fun and write well.

    What it takes
    SOC experience and fluency with MITRE ATT&CK. Strong writing is the real filter in interviews.
    First step
    Write a one-page brief on a threat group targeting your industry and map its techniques to what your SOC can actually see.
  • Detection engineer

    Writes and tunes the rules the SOC runs on, often as code with testing and version control. Suits analysts who keep saying "this alert is noisy, I could fix it."

    What it takes
    Query language skill (SPL, KQL or similar), some Python, and comfort with Git. Most people get in through an internal move.
    First step
    Take the noisiest rule in your queue this week, write down why it misfires, and propose a tuned version to your lead.
  • Cloud security analyst or engineer

    Secures AWS, Azure or Google Cloud: identity and access, logging, misconfiguration findings and guardrails. Suits analysts who already chase cloud alerts and want to fix the causes.

    What it takes
    Hands-on time in at least one cloud. A provider security certification helps, and a free-tier lab account costs little.
    First step
    Open a free-tier account in the cloud your company uses and turn on its audit logging, then look at what a login event records.
  • Penetration tester

    Attacks systems with permission and reports what could be exploited. Suits analysts who enjoy the attacker side of investigations. Entry roles are competitive and usually want proof of hands-on skill.

    What it takes
    Months of practice on legal lab platforms, and often a hands-on offensive certification. Expect a practical exam or take-home in interviews.
    First step
    Work through five beginner machines on a legal practice platform and write a short report for each, as if for a client.
  • Security engineer

    Builds and runs the security tooling: EDR, SIEM pipelines, identity, email security. Suits analysts who like fixing the platform more than working the queue.

    What it takes
    Scripting and systems administration skills. CISSP is common in senior postings and requires five years of experience in two or more of its eight domains, per ISC2 (an Associate path exists).
    First step
    Ask your engineering team for one small tooling task, like a log source onboarding, and document what you did.

Specific moves, step by step

What carries over, what to build, a 90-day plan and your résumé rewritten for each one.

Sample conversation

How a conversation with Carmen starts

Carmen asks before she suggests. An illustrative example, not a real person.

Two years as an L1. I'm tired of the queue and everyone says go GRC.

Two years of triage is useful in GRC, you have seen controls fail. Which tickets did you actually enjoy closing?

The ones where I had to write up what happened and why a control missed it.

That writing is most of GRC work. Want to map your SOC experience against a GRC analyst posting and see what is missing?

Work it out with Carmen, free

30 free minutes with Carmen and the team. No card needed.

Questions & answers

Is moving from SOC to GRC a step down?
No. It is a different track, with more focus on risk, audits and policy and less on live alerts. GRC analysts who understand how attacks really work are valued, and the path leads to risk management and security leadership.
What is the typical SOC analyst career path?
Many people start in IT support or help desk, move into an L1 SOC role, then L2 and L3. From there they specialize: incident response, detection engineering, threat intelligence, cloud security, GRC or security engineering.
How long should I stay in the SOC before moving?
There is no fixed number. Most specialties want you to have handled real incidents and know your tools well. When your questions start being about why things happen rather than how to close the ticket, you are usually ready to look.
Which certification should I get to leave the SOC?
Match it to the role you want. Security+ is a common baseline (CompTIA recommends Network+ and two years in a security or systems administrator role first). CISSP and CISA both require five years of experience. Check real postings for the role you want before paying for anything.

More for security analysts

Change careers